Share via

How to fix: The computer has rebooted from a bugcheck. The bugcheck was:0x0000001e

Aspen Mackay 0 Reputation points
2026-03-03T02:43:58.3266667+00:00

Hi there my computer has been crashing on and off for about a week or so, I've tried reinstalling windows, checking for memory or any system problems but no clear answer. Checked event viewer to see the details of a crash and got the bugcheck error, anyone know what's going on?

The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff8021705fe6a, 0x0000000000000000, 0xffffffffffffffff). A dump was saved in: C:\WINDOWS\MEMORY.DMP. Report Id: 0142f814-00ad-4332-a8b3-49e58471f914.

Link to minidumps that was created: https://1drv.ms/u/c/bbc8d2575e948634/IQA8Dhqji-7WSqJ8tP4MwAepATT-tjDFjOdijBItLjtAcE8?e=GI40k4

ExtensionGallery settings after reading 'SOFTWARE\Microsoft\Debug Engine' registry:
ExtensionGallery ExtensionRepository: Implicit

************* Preparing the environment for Debugger Extensions Gallery repositories **************
   ExtensionRepository : Implicit
   UseExperimentalFeatureForNugetShare : true
   AllowNugetExeUpdate : true
   NonInteractiveNuget : true
   AllowNugetMSCredentialProviderInstall : true
   AllowParallelInitializationOfLocalRepositories : true
   EnableRedirectToChakraJsProvider : false

   -- Configuring repositories
      ----> Repository : LocalInstalled, Enabled: true
      ----> Repository : UserExtensions, Enabled: true

>>>>>>>>>>>>> Preparing the environment for Debugger Extensions Gallery repositories completed, duration 0.000 seconds

************* Waiting for Debugger Extensions Gallery to Initialize **************

>>>>>>>>>>>>> Waiting for Debugger Extensions Gallery to Initialize completed, duration 0.297 seconds
   ----> Repository : UserExtensions, Enabled: true, Packages count: 0
   ----> Repository : LocalInstalled, Enabled: true, Packages count: 46

Microsoft (R) Windows Debugger Version 10.0.29507.1001 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Users\asp3n\OneDrive\Desktop\MEMORY.DMP]
Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.

Symbol search path is: srv*
Executable search path is: 
Windows 10 Kernel Version 19041 MP (16 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Kernel base = 0xfffff802`16a00000 PsLoadedModuleList = 0xfffff802`1762a4e0
Debug session time: Mon Mar  2 23:02:29.129 2026 (UTC - 3:30)
System Uptime: 0 days 0:00:02.805
Loading Kernel Symbols
...............................................................
................................................
Loading User Symbols
PEB is paged out (Peb.Ldr = 000000d8`3f552018).  Type ".hh dbgerr001" for details
Loading unloaded module list
...
For analysis of this file, run !analyze -v
nt!KeBugCheckEx:
fffff802`16dfdf70 48894c2408      mov     qword ptr [rsp+8],rcx ss:fffff48c`ed2732b0=000000000000001e
8: kd> !analyze -v
Loading Kernel Symbols
...............................................................
................................................
Loading User Symbols
PEB is paged out (Peb.Ldr = 000000d8`3f552018).  Type ".hh dbgerr001" for details
Loading unloaded module list
...
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common BugCheck.  Usually the exception address pinpoints
the driver/function that caused the problem.  Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff8021705fe6a, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: ffffffffffffffff, Parameter 1 of the exception

Debugging Details:
------------------

*************************************************************************
***                                                                   ***
***                                                                   ***
***    Either you specified an unqualified symbol, or your debugger   ***
***    doesn't have full symbol information.  Unqualified symbol      ***
***    resolution is turned off by default. Please either specify a   ***
***    fully qualified symbol module!symbolname, or enable resolution ***
***    of unqualified symbols by typing ".symopt- 100". Note that     ***
***    enabling unqualified symbol resolution with network symbol     ***
***    server shares in the symbol path may cause the debugger to     ***
***    appear to hang for long periods of time when an incorrect      ***
***    symbol name is typed or the network symbol server is down.     ***
***                                                                   ***
***    For some commands to work properly, your symbol path           ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: ExceptionRecord                               ***
***                                                                   ***
*************************************************************************
*************************************************************************
***                                                                   ***
***                                                                   ***
***    Either you specified an unqualified symbol, or your debugger   ***
***    doesn't have full symbol information.  Unqualified symbol      ***
***    resolution is turned off by default. Please either specify a   ***
***    fully qualified symbol module!symbolname, or enable resolution ***
***    of unqualified symbols by typing ".symopt- 100". Note that     ***
***    enabling unqualified symbol resolution with network symbol     ***
***    server shares in the symbol path may cause the debugger to     ***
***    appear to hang for long periods of time when an incorrect      ***
***    symbol name is typed or the network symbol server is down.     ***
***                                                                   ***
***    For some commands to work properly, your symbol path           ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: ContextRecord                                 ***
***                                                                   ***
*************************************************************************

KEY_VALUES_STRING: 1

    Key  : AV.Page.Virtual
    Value: 0xffffffffffff0000

    Key  : AV.Type
    Value: Read

    Key  : Analysis.CPU.mSec
    Value: 1734

    Key  : Analysis.Elapsed.mSec
    Value: 1796

    Key  : Analysis.IO.Other.Mb
    Value: 0

    Key  : Analysis.IO.Read.Mb
    Value: 1

    Key  : Analysis.IO.Write.Mb
    Value: 0

    Key  : Analysis.Init.CPU.mSec
    Value: 375

    Key  : Analysis.Init.Elapsed.mSec
    Value: 2784

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 72

    Key  : Analysis.Version.DbgEng
    Value: 10.0.29507.1001

    Key  : Analysis.Version.Description
    Value: 10.2511.5.1 amd64fre

    Key  : Analysis.Version.Ext
    Value: 1.2511.5.1

    Key  : Bugcheck.Code.KiBugCheckData
    Value: 0x1e

    Key  : Bugcheck.Code.LegacyAPI
    Value: 0x1e

    Key  : Bugcheck.Code.TargetModel
    Value: 0x1e

    Key  : Failure.Bucket
    Value: AV_nt!ObLogSecurityDescriptor

    Key  : Failure.Exception.IP.Address
    Value: 0xfffff8021705fe6a

    Key  : Failure.Exception.IP.Module
    Value: nt

    Key  : Failure.Exception.IP.Offset
    Value: 0x65fe6a

    Key  : Failure.Hash
    Value: {0f4293cd-740d-e46d-4c91-6b12af516669}

    Key  : Faulting.IP.Type
    Value: Paged

    Key  : Hypervisor.Enlightenments.Value
    Value: 0

    Key  : Hypervisor.Enlightenments.ValueHex
    Value: 0x0

    Key  : Hypervisor.Flags.AnyHypervisorPresent
    Value: 0

    Key  : Hypervisor.Flags.ApicEnlightened
    Value: 0

    Key  : Hypervisor.Flags.ApicVirtualizationAvailable
    Value: 1

    Key  : Hypervisor.Flags.AsyncMemoryHint
    Value: 0

    Key  : Hypervisor.Flags.CoreSchedulerRequested
    Value: 0

    Key  : Hypervisor.Flags.CpuManager
    Value: 0

    Key  : Hypervisor.Flags.DeprecateAutoEoi
    Value: 0

    Key  : Hypervisor.Flags.DynamicCpuDisabled
    Value: 0

    Key  : Hypervisor.Flags.Epf
    Value: 0

    Key  : Hypervisor.Flags.ExtendedProcessorMasks
    Value: 0

    Key  : Hypervisor.Flags.HardwareMbecAvailable
    Value: 1

    Key  : Hypervisor.Flags.MaxBankNumber
    Value: 0

    Key  : Hypervisor.Flags.MemoryZeroingControl
    Value: 0

    Key  : Hypervisor.Flags.NoExtendedRangeFlush
    Value: 0

    Key  : Hypervisor.Flags.NoNonArchCoreSharing
    Value: 0

    Key  : Hypervisor.Flags.Phase0InitDone
    Value: 0

    Key  : Hypervisor.Flags.PowerSchedulerQos
    Value: 0

    Key  : Hypervisor.Flags.RootScheduler
    Value: 0

    Key  : Hypervisor.Flags.SynicAvailable
    Value: 0

    Key  : Hypervisor.Flags.UseQpcBias
    Value: 0

    Key  : Hypervisor.Flags.Value
    Value: 16908288

    Key  : Hypervisor.Flags.ValueHex
    Value: 0x1020000

    Key  : Hypervisor.Flags.VpAssistPage
    Value: 0

    Key  : Hypervisor.Flags.VsmAvailable
    Value: 0

    Key  : Hypervisor.RootFlags.AccessStats
    Value: 0

    Key  : Hypervisor.RootFlags.CrashdumpEnlightened
    Value: 0

    Key  : Hypervisor.RootFlags.CreateVirtualProcessor
    Value: 0

    Key  : Hypervisor.RootFlags.DisableHyperthreading
    Value: 0

    Key  : Hypervisor.RootFlags.HostTimelineSync
    Value: 0

    Key  : Hypervisor.RootFlags.HypervisorDebuggingEnabled
    Value: 0

    Key  : Hypervisor.RootFlags.IsHyperV
    Value: 0

    Key  : Hypervisor.RootFlags.LivedumpEnlightened
    Value: 0

    Key  : Hypervisor.RootFlags.MapDeviceInterrupt
    Value: 0

    Key  : Hypervisor.RootFlags.MceEnlightened
    Value: 0

    Key  : Hypervisor.RootFlags.Nested
    Value: 0

    Key  : Hypervisor.RootFlags.StartLogicalProcessor
    Value: 0

    Key  : Hypervisor.RootFlags.Value
    Value: 0

    Key  : Hypervisor.RootFlags.ValueHex
    Value: 0x0

    Key  : SecureKernel.HalpHvciEnabled
    Value: 0

    Key  : WER.OS.Branch
    Value: vb_release

    Key  : WER.OS.Version
    Value: 10.0.19041.1


BUGCHECK_CODE:  1e

BUGCHECK_P1: ffffffffc0000005

BUGCHECK_P2: fffff8021705fe6a

BUGCHECK_P3: 0

BUGCHECK_P4: ffffffffffffffff

FILE_IN_CAB:  MEMORY.DMP

FAULTING_THREAD:  ffffac875ae8d040

EXCEPTION_PARAMETER1:  0000000000000000

EXCEPTION_PARAMETER2:  ffffffffffffffff

READ_ADDRESS: unable to get nt!PspSessionIdBitmap
 ffffffffffffffff 

BLACKBOXNTFS: 1 (!blackboxntfs)


PROCESS_NAME:  smss.exe

IP_IN_PAGED_CODE: 
nt!ObLogSecurityDescriptor+9a
fffff802`1705fe6a 48395f10        cmp     qword ptr [rdi+10h],rbx

STACK_TEXT:  
fffff48c`ed2732a8 fffff802`16e3fa29     : 00000000`0000001e ffffffff`c0000005 fffff802`1705fe6a 00000000`00000000 : nt!KeBugCheckEx
fffff48c`ed2732b0 fffff802`16e128ec     : 00000000`64536553 fffff802`16d3c19f 00000000`00000103 00000000`00000000 : nt!KiDispatchException+0x1cc749
fffff48c`ed273970 fffff802`16e0dcef     : ffffc788`e75f4abc ffffc788`e75f4af0 8000000b`00000000 ffffc788`e75f4abc : nt!KiExceptionDispatch+0x12c
fffff48c`ed273b50 fffff802`1705fe6a     : 00000000`00000000 00000000`00000001 00000000`00000000 ffffac87`00000000 : nt!KiGeneralProtectionFault+0x32f
fffff48c`ed273ce0 fffff802`1705fbca     : 00000000`00000084 fffff48c`ed273d90 00000000`00000010 00000000`00000084 : nt!ObLogSecurityDescriptor+0x9a
fffff48c`ed273d60 fffff802`17104d4e     : 00000000`00000000 fffff48c`ed273ec0 ffffac87`5ae9f200 00000000`00000000 : nt!SeDefaultObjectMethod+0x5a
fffff48c`ed273dc0 fffff802`17049520     : ffffffff`ffffffff ffffac87`5ab3f080 ffffac87`5ab3f080 ffffffff`ffffffff : nt!ObInsertObjectEx+0x3ee
fffff48c`ed274050 fffff802`17048ee0     : ffffac87`5ab3f080 ffffac87`5311c040 00000000`00000000 fffff48c`ed274174 : nt!PspInsertThread+0x4f8
fffff48c`ed274110 fffff802`170d0202     : ffffac87`5ae96040 00000000`00000002 ffffac87`530aebc0 00000000`00000000 : nt!PspCreateThread+0x294
fffff48c`ed2743d0 fffff802`1718f76d     : fffff802`17600f40 00000000`00000000 fffff802`17600f40 fffff802`14df3000 : nt!PsCreateSystemThreadEx+0x152
fffff48c`ed274720 fffff802`1718f6bf     : fffff802`00000001 00000000`000000c8 fffff802`17601468 00000000`00000006 : nt!CmpCreateRegistryThread+0x59
fffff48c`ed2747b0 fffff802`1719006d     : 00000000`00000000 fffff48c`ed2749b0 00000000`00000000 00000000`00000000 : nt!CmpInitializeSystemHivesLoad+0x1eb
fffff48c`ed2748a0 fffff802`1718d4a0     : ffffac87`5ae8d040 00000000`00000000 fffff48c`ed2749b0 00000000`c0000001 : nt!CmCompleteRegistryInitialization+0x61
fffff48c`ed274900 fffff802`16e11f08     : ffffd281`388aa6a8 00000000`00000000 00000000`00000001 00000000`00000001 : nt!NtInitializeRegistry+0x60
fffff48c`ed274930 fffff802`16e02d60     : fffff802`1718d46a 00000000`00000084 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
fffff48c`ed274ac8 fffff802`1718d46a     : 00000000`00000084 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiServiceLinkage
fffff48c`ed274ad0 fffff802`16e11f08     : ffffac87`5ae8d040 ffffac87`5ae8d040 fffff48c`00000000 ffffac87`00000000 : nt!NtInitializeRegistry+0x2a
fffff48c`ed274b00 00007ffe`fb8ef664     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
000000d8`3f3af2a8 00000000`00000000     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffe`fb8ef664


SYMBOL_NAME:  nt!ObLogSecurityDescriptor+9a

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

IMAGE_VERSION:  10.0.19041.6926

STACK_COMMAND: .process /r /p 0xffffac875ae96040; .thread 0xffffac875ae8d040 ; kb

BUCKET_ID_FUNC_OFFSET:  9a

FAILURE_BUCKET_ID:  AV_nt!ObLogSecurityDescriptor

OS_VERSION:  10.0.19041.1

BUILDLAB_STR:  vb_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {0f4293cd-740d-e46d-4c91-6b12af516669}

Followup:     MachineOwner
---------


Windows for home | Windows 10 | Performance and system failures
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Jonathan Deives 67,725 Reputation points Independent Advisor
    2026-03-03T03:18:30.5433333+00:00

    See if your computer is creating minidump files.

    To find these files, this is the path "C:\Windows\Minidump".

    First copy and paste all the minidump files you have to another folder and then zip it. Then upload the ZIP file to the cloud OneDrive.

    Choose to share or right click and get the share link.

    Please post the link to the ZIP file here so it can be reviewed.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.